| Summary: | Certificate re-deploy script cause an outage to entire OpenShift cluster because of router restarts (causing broken connectivity to master). | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Eric Rich <erich> |
| Component: | Installer | Assignee: | Andrew Butcher <abutcher> |
| Status: | CLOSED NOTABUG | QA Contact: | Johnny Liu <jialiu> |
| Severity: | urgent | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 3.3.0 | CC: | aos-bugs, jokerman, mmccomas |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2016-10-27 16:00:20 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Eric Rich
2016-10-25 22:59:48 UTC
Once the CA has been replaced the running routers will be unable to create new routes until router pods have been recreated as a result of the node evacuation. Existing routes will continue to be accessible and should continue to be accessible during pod evacuation assuming router has been scaled. Tested by installing cluster, creating pod+route, running cert redeploy w/ CA replacement without node evacuation and ensuring that pod is still routable. |